On Tue, Sep 20, 2011 at 08:37:35PM +0200, Richard Könning wrote:
> 
> Please read http://www.openssl.org/~bodo/tls-cbc.txt, problem #2.
> You then see that the problem is already addressed in OpenSSL
> 0.9.6d, over seven years ago. See also 
> http://citeseerx.ist.psu.edu/viewdoc/download?doi=10.1.1.61.5887&rep=rep1&type=pdf,
> section 6, subsection "OpenSSL and the Empty Message".

You might also want to read:
http://www.imperialviolet.org/2011/09/23/chromeandbeast.html


Kurt

______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
Development Mailing List                       openssl-dev@openssl.org
Automated List Manager                           majord...@openssl.org

Reply via email to